Characterization and Classification of Internet Backbone Traffic
Doktorsavhandling, 2010

We contribute to an improved understanding of Internet traffic characteristics by measuring and analyzing modern Internet backbone data. We start the thesis with an overview of several important considerations for passive Internet traffic collection on large-scale network links. The lessons learned from a successful measurement project on academic Internet backbone links can serve as guidelines to others setting up and performing similar measurements. The data from these measurements are the basis for the analyses made in this thesis. As a first result we present a detailed characterization of packet headers, which reveals protocol-specific features and provides a systematic survey of packet header anomalies. The packet-level analysis is followed by a characterization on the flow-level, where packets are correlated according to their communication endpoints. We propose a method and accompanying metrics to assess routing symmetry on a flow-level based on passive measurements. This method will help to improve traffic analysis techniques. We used the method on our data, and the results suggest that routing symmetry is uncommon on non- edge Internet links. We then confirm the predominance of TCP as the transport protocol in backbone traffic. However, we observe an increase of UDP traffic during the last few years, which we attribute to P2P signaling traffic. We also analyze further flow characteristics such as connection establishment and termination behavior, which reveals differences among traffic from various classes of applications. These results show that there is a need to make a more detailed analysis, i.e., classification of traffic according to network application. To accomplish this, we review state-of-the-art traffic classification approaches and subsequently propose two new methods. The first method provides a payload-independent classification of aggregated traffic based on connection patterns. This provides a rough traffic decomposition in a privacy sensitive way. Second, we present a classification method for fine-grained protocol identification by utilizing statistical packet and flow features. Preliminary results indicate that this method is capable of accurate classification in a simple and efficient way. We conclude the thesis by discussing limitations in current Internet measurement research. Considering the role of the Internet as a critical infrastructure of global importance, a detailed understanding of Internet traffic is essential. This thesis presents methods and results contributing additional perspectives on global Internet characteristics at different levels of granularity.








HA2 (Hörsalsvägen 4)
Opponent: Prof. Vern Paxson, University of California, Berkeley, USA


Wolfgang John

Chalmers, Data- och informationsteknik, Nätverk och system

Statistical Protocol IDentification with SPID: Preliminary Results

Swedish National Computer Networking Workshop,; (2009)

Paper i proceeding

Estimating Routing Symmetry on Single Links by Passive Flow Measurements

IWCMC'10: 6th International Wireless Communications & Mobile Computing Conference,,; (2010)p. 473--478-

Paper i proceeding

Trends and Differences in Connection-behavior within Classes of Internet Backbone Traffic

Lecture Notes in Computer Science,; Vol. 4979/2008(2008)p. 192-201

Paper i proceeding

Analysis of Internet Backbone Traffic and Header Anomalies Observed

IMC '07: Proceedings of the 7th ACM SIGCOMM conference on Internet measurement,; (2007)p. 111-116

Paper i proceeding

Differences between In- and Outbound Internet Backbone Traffic

TERENA Networking Conference 2007, Copenhagen, DK,; (2007)

Paper i proceeding

Heuristics to Classify Internet Backbone Traffic based on Connection Patterns

ICOIN '08: Proceedings of the 22nd International Conference on Information Networking,; (2008)

Paper i proceeding

State of the Art in Traffic Classification: A Research Review

PAM '09: 10th International Conference on Passive and Active Measurement, Student Workshop,; (2009)

Poster (konferens)

Detection of malicious Traffic on Backbone links via Packet Header Analysis

Campus-Wide Information Systems,; Vol. 25(2008)p. 342 - 358

Artikel i vetenskaplig tidskrift

Analysis of UDP Traffic Usage on Internet Backbone Links

Saint '09: Ninth Annual International Symposium on Applications and the Internet,; (2009)p. 280 - 281

Paper i proceeding

Passive Internet Measurement: Overview and Guidelines based on Experiences

Computer Communications,; Vol. 33(2010)p. 533-550

Artikel i vetenskaplig tidskrift





Doktorsavhandlingar vid Chalmers tekniska högskola. Ny serie: 3044

Technical report D - Department of Computer Science and Engineering, Chalmers University of Technology and Göteborg University: 65

HA2 (Hörsalsvägen 4)

Opponent: Prof. Vern Paxson, University of California, Berkeley, USA